ASGARD← Home

Privacy Policy

Effective 28 September 2026

This policy explains what personal data ASGARD collects, why, and what you can do about it. It follows Qatar's Law No. 13 of 2016 on Protecting Personal Data Privacy (the "PDPPL") and, for people in the EU, EEA and UK, the GDPR (see section 12). Terms such as Client, Proposal, Project, Support & Growth Plan, Third-Party Platforms and Our Applications have the meaning given in our Terms and Conditions.

1. Who is responsible

ASGARD, a software development studio based in Doha, State of Qatar, is the controller of personal data processed through the website asgardhq.com (the "Website") and in our work with Clients and prospective Clients, except where we process personal data on a Client's behalf, as described in section 7. For anything about privacy, write to office@asgardhq.com.

2. What we collect

We need contact and billing details to prepare a Proposal and to carry out a Project; without them we cannot work with you. Anything else you share is optional. If your employer or a colleague gives us your details for a Project, we receive them from them.

We do not ask for sensitive data (such as health, religion or criminal records), and we do not buy contact lists. We have no contact forms: you reach us by email.

3. No cookies, privacy-friendly statistics

The Website sets no cookies of its own and carries no advertising trackers or social-media pixels. Our fonts are served from our own site, so loading a page does not contact font providers.

To understand how the Website is used, we use Cloudflare Web Analytics. It does not use cookies or local storage, does not fingerprint your device, does not follow you across other websites and does not build a profile of you. When a page loads, a small script from Cloudflare records the page viewed, the referring page, the browser and device type, the country (derived from the IP address) and how fast the page loaded. We see only aggregated numbers, never individual visitors.

If bot protection is switched on, Cloudflare may set strictly necessary security cookies, such as __cf_bm (which expires after 30 minutes of inactivity) or cf_clearance (set after a visitor passes a check). They are used only to tell people from automated bots. Our Cloudflare account shows us aggregated traffic statistics and, for requests that trigger a security rule, individual log entries with the IP address, approximate location, browser details and page requested. We use them only to protect the Website, and they are kept only for the short periods described in section 8.

Because we do not track visitors over time or across other websites, and do not allow third parties to do so on the Website, the Website does not respond differently to browser "Do Not Track" signals.

4. Why we use your data

We process personal data only with your consent or where it is necessary for a lawful purpose, as the PDPPL allows. We do not send you marketing emails without your prior consent, and we do not make decisions about you based solely on automated processing.

5. Who we share it with

We do not sell, rent or trade personal data. We share it with the following categories of recipients:

Cloudflare acts as our service provider (processor) under its data processing terms. Google provides our email inbox under Google's own terms and privacy policy (policies.google.com/privacy).

6. Transfers across borders

We are based in Qatar, and our service providers operate worldwide, so your data may be processed outside your country, including in the United States and the EU. We transfer data across borders only where this is consistent with the PDPPL and the data remains protected.

7. When we act for our Clients

In some Projects we process personal data of our Clients' own customers, for example conversations handled by an AI assistant or bot. For that data, the Client is the controller and ASGARD is a processor: we process it only on the Client's documented instructions, keep it confidential and secure, and use sub-processors (such as hosting, AI model and messaging providers) only as agreed with the Client. Where data protection law requires it, including the GDPR and UK GDPR, we sign a data processing agreement with the Client before we process that data; for Clients in the EU, EEA or UK it includes the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. For other Clients it is available on request. If you are a customer of one of our Clients, please send requests about your data to that business; we will help it respond.

8. How long we keep it

After that, we delete or anonymise the data.

9. Security

We use encrypted connections, give access only to people who need it, and require our providers to protect data. No system is perfectly secure. If a breach is likely to harm you, we will notify you and the competent authority as the law requires.

10. Your rights

Under the PDPPL you may be told whether and why we process your data; access and review it and get a copy; ask us to correct it; object to processing that is not necessary for its purpose, or is excessive, discriminatory, unfair or unlawful; ask us to erase it in those cases or once the purpose has ended; be told if we have disclosed inaccurate data about you; and withdraw your consent at any time. Write to office@asgardhq.com. We may ask you to confirm your identity and will reply within 30 days. You can also complain to the National Cyber Security Agency (NCSA), the competent authority for personal data protection in Qatar.

11. Children

The Website and our Services are meant for businesses and adults. We do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, write to us and we will delete it.

12. If you are in the EU, EEA or UK

Where the EU General Data Protection Regulation (Regulation (EU) 2016/679), or the UK GDPR and the Data Protection Act 2018, apply to our processing:

13. Our Applications

Every application or platform that ASGARD itself releases and operates is governed by that application's own terms, privacy policy and refund rules, published inside or for it. For data processed in that application, its own privacy policy prevails over this one. This policy covers the Website and our bespoke client Services.

14. Changes

If this policy changes, the new version appears on the Website with a new effective date. If a change materially affects data you have already given us, we will tell you by email.

15. Contact

Privacy requests and questions: office@asgardhq.com